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Amendments to the Claims: 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

Listing of Claims: 

What is claimed is: 

1.-29. (Cancelled) 

30. (Currently Amended) An apparatus arranged for receiving an access 
request in a telecommunication core network (CN) from an entity a wireless local 
access network-access server (WLAN-AS) in [[an]] a wireless local access network 
(WLAN) whor e the access request sent by a user equipment (UE) of a user w i th a 
user's oquipmont (UE) acoossos through , the user being a subscriber of the 
telecommunication CN and being identified by a user's identifier included in the access 
request, the apparatus having a means for carrying out an authentication procedure 
with the UE through th o access notwork (WLAN) WLAN-AS in order to authenticate the 
user; and a means for computing at least one secret user's key (Kc) usable as 
cryptographic material, the apparatus comprising: 

a means for deriving from the cryptographic material a user's shared key 
(SSQ_key 1 ) intended for single sign on ( SSO) purposes; and 

a means for sending the user's shared key (SSO koy 1) along with the user's 
identifier towards a SSO session manager (SSO_SM) serving a service network (SN) of 
a mobile network operator (MNO) (MNO-SN) . 

31 . (Currently Amended) The apparatus of claim 30, further comprising means 
for being notified that a session at [[the]] an access level of the WLAN-AS has been 
established, this notification triggering the sending of the user's shared key (SSO_k e y - 
1) towards th e s e ssion manag e r (SSO_SM) to a SSO session manager serving the 
service n e twork (SN) MNO-SN . 
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32. (Currently Amended) The apparatus of claim 31 , further comprising means 
for being notified that a session at the access level of the WLAN-AS has been 
terminated, and means for forwarding this notification towards the s e ssion manager 
(SSQ_SM) to a SSO session manager serving the MNO-SN serv i ce n e twork (SN) in 
order to inactivate a current master session for the user. 

33. -45. (Canceled) 

46. (Currently Amended) A user's user equipment (UE) usable by a user with 
a subscription in a telecommunication network, and arranged to access a 
to l ocommunication service network (SN) of a mobile network operator (MNO)(MNO-SN) 
through [[an]] a wireless local access network (WLAN), the user's oqu i pmont (UE) UE 
having means for carrying out an authentication procedure to authenticate the user with 
a core network (CN) , whoro tho user ho l ds tho subscr i ption, through the access network 
(WLAN) WLAN access server (WLAN-AS) and means for computing at least one secret 
user's key [[(Kc)]] usable as cryptographic material, the user's equipment UE 
comprising: 

a means for deriving from the cryptographic material a user's shared key 

(SSO_koy 2) intended for single sign on ( SSO) purposes; 

a repository for storing the user's shared key (SSO_koy 2) ; and 

a means for confirming to a session manager of the MNO-SN the user's shared 

key (SSQ_koy 2) stored at the UE us e r's equipment towards an entity (SAAN, 

SSO_SM) in tho sorv i co n e twork (SN) . 

47. (Currently Amended) The user's oqu i pmont UE of claim 46, wherein the 
means for confirming the user's shared key to the session manager of the MNO-SN 
includes a means for downloading an SSO plug-in from an e ntity (SAAN, SSO_SM) in 
th o so rvico network (SN) , the session manager of the MNO-SN. the SSO plug-in 
running for confirming back operable to confirm the user's shared key. 
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48. (Currently Amended) The usor'c oquipmont UE of claim 46, wherein the 
means for confirming to a session manager of the MNO-SN the user's shared key 
includes a means for processing the user's shared key (SSO_k e y - 2) to obtain a key 
code (MAC(SSO_koy 2)) to be transmitted to the session manager of the MNO-SN an 
ent i ty (SAAN, SSO_SM) in th e sorv i co network (SN) . 

49. (Currently Amended) The user's oqu i pmont UE of claim 46, further 
comprising means for receiving an SSO cookie from an ontity (SAAN, SSQ_SM) in the 
sorvico network, the session manager of the MNO-SN. the SSO cookie to be included 
in all further service requests from the user's oquipmont UE as an SSO token. 

50. -58 (Cancelled) 
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